Link to home
Start Free TrialLog in
Avatar of Jim Metcalf
Jim MetcalfFlag for United States of America

asked on

trying to add first 2008 dc to domain dns problems

Im going through the dcpromo process for my first 2008 r2 dc.  forestprep and domainprep went through with no errors. now in the process of promoting it i get the.

A delegation for the dns server cannot be created because authoritative parent zone cannot be found ot ir does not run windows dns server.


i looked it up that problem and most people thought the cause was because it was the first dns server in the domain.  this is not the case.  on the network settings on the new 2008 soon to be dc... it is pointing to an already existing dc with active directory integrated dns.  
so i go over to the 2003 r2 dc with dns running and go to the event viewer for dns and i see all these  event id 4004 errors in the event viewer.  i don't think my dns is functioning properly.  im on hold on the dcpromo install.

attached are the 2 errors i am seeing
dcpromo-error.jpg
Avatar of Jim Metcalf
Jim Metcalf
Flag of United States of America image

ASKER

here is the screen shot of the error on the already existing 2003 r2 domain controller with active directory integrated dns
dns-error-on-existing-dc.JPG
ASKER CERTIFIED SOLUTION
Avatar of Darius Ghassem
Darius Ghassem
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
in the dns mmc on the existing 2003 r2 domain controller.
there is no msdsc.domain.com in the forward lookup zones.
in the zone with the correct name... the _msdcs folder is not greyed out.
I don't have a folder _msdcs underneath the forward lookup zones.
better-look.JPG
everything passed dcdiag /dnsass except for this one

 An Error Event occured.  EventID: 0x825A0011
            Time Generated: 04/12/2010   15:20:12
            (Event String could not be retrieved)
         ......................... "Servername" failed test systemlog
Run dcdiag then post.

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests
   
   Testing server: Site 1\SERVERNAME
      Starting test: Connectivity
         ......................... SERVERNAME passed test Connectivity

Doing primary tests
   
   Testing server: Site 1\SERVERNAME
      Starting test: Replications
         ......................... SERVERNAME passed test Replications
      Starting test: NCSecDesc
         ......................... SERVERNAME passed test NCSecDesc
      Starting test: NetLogons
         ......................... SERVERNAME passed test NetLogons
      Starting test: Advertising
         ......................... SERVERNAME passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... SERVERNAME passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... SERVERNAME passed test RidManager
      Starting test: MachineAccount
         Warning:  Attribute userAccountControl of SERVERNAME is: 0x82020 = ( UF_PASSWD_NOTREQD | UF_SERVER_TRUST_ACCOUNT | UF_TRUSTED_FOR_DELEGATION )
         Typical setting for a DC is 0x82000 = ( UF_SERVER_TRUST_ACCOUNT | UF_TRUSTED_FOR_DELEGATION )
         This may be affecting replication?
         ......................... SERVERNAME passed test MachineAccount
      Starting test: Services
         ......................... SERVERNAME passed test Services
      Starting test: ObjectsReplicated
         ......................... SERVERNAME passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... SERVERNAME passed test frssysvol
      Starting test: frsevent
         ......................... SERVERNAME passed test frsevent
      Starting test: kccevent
         ......................... SERVERNAME passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x825A0011
            Time Generated: 04/12/2010   15:20:12
            (Event String could not be retrieved)
         ......................... SERVERNAME failed test systemlog
      Starting test: VerifyReferences
         ......................... SERVERNAME passed test VerifyReferences
   
   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
   
   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
   
   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
   
   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
   
   Running partition tests on : ci
      Starting test: CrossRefValidation
         ......................... ci passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... ci passed test CheckSDRefDom
   
   Running enterprise tests on : "domain name"
      Starting test: Intersite
         ......................... "domain name" passed test Intersite
      Starting test: FsmoCheck
         ......................... "domain name" passed test FsmoCheck
Make sure the times are sync with the correct dates applied.
the times on the domain controllers are in sync.

one thing of note.  is that i have 2 sites in sites and services.  the default-first-site-name doesnt seem to be used.
the site for my domain has servers listed
Do you have another DNS server that you can point too?
yes
i made the primary dns server on the 2008 server i am promoting to both of my dns servers and i get the same error.
cannot find authoritative server
one more sympton...
nslookup has the error

***Can't find server name for address (ip address of dns server): Non-existent domain
Default Server: UnKnown
Address: (ip address of dns server)

the same error occurs from nslookup from a either workstation on the domain or even on the dc that is the dns server itself.
Looks like you have two NICs on this server. Are they teamed or are they on different networks? Or two connections to the same network?
both servers have 2 nics.
both of them have one disabled and one enabled
each nic on each server seemed to be configured correctly
each dns server points to the other as its preferred dns server and to itself for the alternate dns server
OK - looked to me like in your screen capture both NICs were active. If you try a simple ping by server name from the new server to the DNS server, what do you get? How about if you do an nslookup from the new server to the existing DC? If you run netdiag on the both servers, what do you get? Please post results.
the 2008 r2 server doesnt seem to run netdiag (this is the server i am trying to promote)
on the other server the results are as follows (domain controller 2003 r2)


Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests
   
   Testing server: 1CityHallSite\servername
      Starting test: Connectivity
         ......................... servername passed test Connectivity

Doing primary tests
   
   Testing server: 1CityHallSite\servername
      Starting test: Replications
         ......................... servername passed test Replications
      Starting test: NCSecDesc
         ......................... servername passed test NCSecDesc
      Starting test: NetLogons
         ......................... servername passed test NetLogons
      Starting test: Advertising
         ......................... servername passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... servername passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... servername passed test RidManager
      Starting test: MachineAccount
         Warning:  Attribute userAccountControl of servername is: 0x82020 = ( UF_PASSWD_NOTREQD | UF_SERVER_TRUST_ACCOUNT | UF_TRUSTED_FOR_DELEGATION )
         Typical setting for a DC is 0x82000 = ( UF_SERVER_TRUST_ACCOUNT | UF_TRUSTED_FOR_DELEGATION )
         This may be affecting replication?
         ......................... servername passed test MachineAccount
      Starting test: Services
         ......................... servername passed test Services
      Starting test: ObjectsReplicated
         ......................... servername passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... servername passed test frssysvol
      Starting test: frsevent
         ......................... servername passed test frsevent
      Starting test: kccevent
         ......................... servername passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x825A0011
            Time Generated: 04/12/2010   15:20:12
            (Event String could not be retrieved)
         ......................... servername failed test systemlog
      Starting test: VerifyReferences
         ......................... servername passed test VerifyReferences
   
   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
   
   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
   
   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
   
   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
   
   Running partition tests on : ci
      Starting test: CrossRefValidation
         ......................... ci passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... ci passed test CheckSDRefDom
   
   Running enterprise tests on : domain_name
      Starting test: Intersite
         ......................... domain_name passed test Intersite
      Starting test: FsmoCheck
         ......................... domain_name passed test FsmoCheck
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
sorry hypercat
im away from work now.
ill run it tomorrow and get back to you
Netdiag is not a tool in 2008 servers.

Post dcdiag /test:dns

And ipconfig /all
netdiag results from the 2003 r2 dc


.......................................

    Computer Name: servername
    DNS Host Name: servername.domainname
    System info : Microsoft Windows Server 2003 (Build 3790)
    Processor : x86 Family 15 Model 2 Stepping 5, GenuineIntel
    List of installed hotfixes :
        KB911564
        KB921503
        KB923561
        KB925398_WMP64
        KB925876
        KB925902
        KB926122
        KB927891
        KB928090-IE7
        KB929123
        KB929969
        KB930178
        KB931768-IE7
        KB931784
        KB931836
        KB932168
        KB933360
        KB933566-IE7
        KB933729
        KB933854
        KB935839
        KB935840
        KB935966
        KB936021
        KB936357
        KB936782
        KB938127-IE7
        KB938464
        KB941202
        KB941568
        KB941569
        KB941644
        KB941672
        KB941693
        KB942763
        KB942830
        KB942831
        KB943055
        KB943460
        KB943484
        KB943485
        KB944533-IE7
        KB944653
        KB945553
        KB946026
        KB948496
        KB948590
        KB948745
        KB949014
        KB950759-IE7
        KB950760
        KB950762
        KB950974
        KB951066
        KB951072-v2
        KB951698
        KB951746
        KB951748
        KB952004
        KB952069
        KB952954
        KB953155
        KB953298
        KB954155
        KB954211
        KB954550-v5
        KB954600
        KB955069
        KB955759
        KB955839
        KB956390-IE7
        KB956391
        KB956572
        KB956744
        KB956802
        KB956803
        KB956841
        KB956844
        KB957095
        KB957097
        KB958215-IE7
        KB958644
        KB958687
        KB958690
        KB958869
        KB959426
        KB960225
        KB960714-IE7
        KB960715
        KB960803
        KB960859
        KB961063
        KB961064
        KB961118
        KB961260-IE7
        KB961371-v2
        KB961373
        KB961501
        KB963027-IE7
        KB967715
        KB967723
        KB968389
        KB968537
        KB968816
        KB969059
        KB969805
        KB969883
        KB969897-IE7
        KB969897-IE8
        KB969898
        KB969947
        KB970238
        KB970483
        KB970653-v3
        KB971032
        KB971468
        KB971486
        KB971557
        KB971633
        KB971657
        KB971737
        KB971961-IE8
        KB972260-IE8
        KB972270
        KB973037
        KB973346
        KB973354
        KB973507
        KB973525
        KB973540
        KB973687
        KB973815
        KB973869
        KB973904
        KB973917
        KB974112
        KB974318
        KB974392
        KB974455-IE8
        KB974571
        KB975025
        KB975254
        KB975467
        KB975560
        KB975713
        KB976098-v2
        KB976325-IE8
        KB976662-IE8
        KB976749-IE8
        KB977165
        KB977290
        KB977914
        KB978037
        KB978207-IE8
        KB978251
        KB978262
        KB978706
        KB979306
        KB980182-IE8
        Q147222


Netcard queries test . . . . . . . : Passed



Per interface results:

    Adapter : 192.168.1.3

        Netcard queries test . . . : Passed

        Host Name. . . . . . . . . : servername
        IP Address . . . . . . . . : 10.100.1.1
        Subnet Mask. . . . . . . . : 255.255.0.0
        Default Gateway. . . . . . : 10.100.0.1
        Primary WINS Server. . . . : 192.168.1.4
        Dns Servers. . . . . . . . : 10.100.1.2
                                     10.100.1.1

        IpConfig results . . . . . : Failed
            Pinging the Primary WINS server 192.168.1.4 - not reachable

        AutoConfiguration results. . . . . . : Passed

        Default gateway test . . . : Passed

        NetBT name test. . . . . . : Passed
        [WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenger Service', <20> 'WINS' names is missing.

        WINS service test. . . . . : Failed
            The test failed.  We were unable to query the WINS servers.


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
    List of NetBt transports currently configured:
        NetBT_Tcpip_{13F11C29-A7BA-4A6F-9944-21729B373461}
    1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed
    [WARNING] You don't have a single interface with the <00> 'WorkStation Service', <03> 'Messenger Service', <20> 'WINS' names defined.


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Passed
    PASS - All the DNS entries for DC are registered on DNS server '10.100.1.2' and other DCs also have some of the names registered.
    PASS - All the DNS entries for DC are registered on DNS server '10.100.1.1' and other DCs also have some of the names registered.


Redir and Browser test . . . . . . : Passed
    List of NetBt transports currently bound to the Redir
        NetBT_Tcpip_{13F11C29-A7BA-4A6F-9944-21729B373461}
    The redir is bound to 1 NetBt transport.

    List of NetBt transports currently bound to the browser
        NetBT_Tcpip_{13F11C29-A7BA-4A6F-9944-21729B373461}
    The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Skipped


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
    No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

    Note: run "netsh ipsec dynamic show /?" for more detailed information


The command completed successfully
dcdiag results from the 2003 r2 domain controller


Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests
   
   Testing server: ThomasvilleCityHallSite\THMVFS1
      Starting test: Connectivity
         ......................... THMVFS1 passed test Connectivity

Doing primary tests
   
   Testing server: ThomasvilleCityHallSite\THMVFS1

DNS Tests are running and not hung. Please wait a few minutes...
   
   Running partition tests on : ForestDnsZones
   
   Running partition tests on : DomainDnsZones
   
   Running partition tests on : Schema
   
   Running partition tests on : Configuration
   
   Running partition tests on : ci
   
   Running enterprise tests on : ci.thomasville.nc.us
      Starting test: DNS
         ......................... ci.thomasville.nc.us passed test DNS
dcdiag results from the 2008 server i am trying to promote to a dc

Directory Server Diagnosis

Performing initial setup:
Trying to find home server....
****Error:  Servername is not a directory Server.  Must Specify /s:<Directory SErver> o9r /n?naming contxt? or nothing ot use he local machine.
Error: could not find home server
Remove the WINS IP address.
I second dariusq's comment - remove the WINS IP address on your DC.
removed....
dc will still not promote
What IP address and subnet mask are you using on the new 2008 server? Can it ping the 2003 DC by name? By IP address?
The additional information message that you posted above refers to creating a read-only domain controller.  Is that what you're trying to do?
Something small is not correct.
im looking at the reverse dns zones and something seems a little strange.

my network is a 10.100.0.0\16
the reverse zone is 0.100.10.in-addr.arpa

shouldnt the reverse zone be
100.10.in-addr.arpa
thanks for all the help guys.
i caved and used microsoft support
Glad you found a solution, even if you did have to call M'soft.  It would be good of you to post the solution here in case it might be helpful for others having similar issues.
Cheers!
Deb